Back to Intelligence

CVE-2026-14378, CVE-2026-19660, CVE-2026-97637: Three Critical WordPress Plugin Authentication Bypass Flaws (CVSS 9.8) — Detection and Remediation Guide

SA
Security Arsenal Team
October 2, 2026
12 min read

In the last three days, NVD published three CRITICAL, network-exploitable CVEs affecting WordPress plugins, each carrying a CVSS score of 9.8. This is the kind of cluster that demands immediate triage from any organization running a public-facing WordPress estate — and given that WordPress powers roughly 40%+ of the web, the blast radius here is enormous.

The three vulnerabilities:

  • CVE-2026-14378 (CVSS 9.8) — DevKit Pro plugin: Authentication Bypass Leading to Administrator Account Takeover, affecting all versions up to and including 2.3.0.
  • CVE-2026-19660 (CVSS 9.8) — Divi Membership plugin: Authentication Bypass in all versions up to the patched release (NVD details truncated at time of writing — treat all deployed versions as suspect until the vendor advisory is reviewed).
  • CVE-2026-97637 (CVSS 9.8) — JSON API Auth plugin: Authentication Bypass via Cached Session Cookie handling.

All three are network-vector, meaning an unauthenticated remote attacker can exploit them over HTTP/HTTPS with no prior access, no user interaction, and — in the case of CVE-2026-14378 — walk away with full administrative control of the site. A compromised WordPress admin is rarely the end goal; it is the foothold for webshell deployment, SEO spam injection, malvertising redirects, credential harvesting from customer databases, and lateral movement into hosting infrastructure. If your organization runs these plugins, or hosts WordPress for clients, this is a patch-now, hunt-immediately situation.

Technical Analysis

Affected Products and Versions

CVEPluginAffected VersionsCVSSVector
CVE-2026-14378DevKit Pro≤ 2.3.09.8Network, unauthenticated
CVE-2026-19660Divi MembershipCheck vendor advisory9.8Network, unauthenticated
CVE-2026-97637JSON API AuthCheck vendor advisory9.8Network, unauthenticated

CVE-2026-14378 — DevKit Pro: The Trust-the-Cookie Failure

This is the most instructive bug of the three and a textbook example of why client-supplied identity data must never be authoritative. The DevKit Pro plugin implements a user-switching feature with a revert_switch handler intended to return an administrator to their original session. The handler trusts an attacker-controlled original_user_id cookie as the privileged identity to revert to.

The root cause is in verify_nonce_and_capability(): the function checks the wrong value — it validates against the manipulated state rather than verifying the caller's actual authenticated identity and capability. The practical attack chain:

  1. Attacker sends an HTTP request to the revert_switch handler with a crafted original_user_id cookie set to a known administrator user ID (user ID 1 is the default admin on most WordPress installs).
  2. The handler accepts the cookie value as ground truth and switches the attacker's session to the administrator account.
  3. Attacker now holds an authenticated admin session — full plugin/theme editor access, user management, and typically code execution via plugin uploads or theme file editing.

No credentials. No prior access. Just a cookie. This is CWE-639 (Authorization Bypass Through User-Controlled Key) meeting CWE-287 (Improper Authentication), and it is trivially scriptable — which means mass scanning and automated exploitation typically follow within days of public disclosure.

CVE-2026-19660 — Divi Membership

The published NVD summary confirms an authentication bypass in the Divi Membership plugin at CVSS 9.8, affecting versions up to the fix. Divi is one of the most widely deployed theme ecosystems in the WordPress world, so even a membership plugin in that family carries significant exposure. Until the full vendor advisory is reviewed, treat this as an unauthenticated access-to-account flaw and prioritize it equivalently to CVE-2026-14378.

CVE-2026-97637 — JSON API Auth: Cached Session Cookie Bypass

This flaw involves authentication bypass through cached session cookie handling in the JSON API Auth plugin, which exposes WordPress authentication over a REST-style API. Cache-layer auth bugs are dangerous because they undermine the token validation logic entirely — a stale, replayed, or improperly cached session token can be accepted as valid, allowing an attacker to authenticate as another user without credentials. For defenders, this means exploitation attempts may look like legitimate API authentication requests, which raises the bar for detection: you must hunt on behavioral anomalies (impossible session reuse, token replay from new source IPs, API auth success without a corresponding prior token issuance) rather than malformed requests.

Exploitation Status

At time of writing, none of the three CVEs appear in the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been publicly confirmed in the disclosure summary. Do not let that lower your urgency. WordPress plugin auth bypasses with public technical details — especially one as mechanically simple as a forged cookie — historically see mass exploitation within days. The disclosure is public; assume working exploit code exists or is imminent, and hunt retrospectively for the past several days of traffic.

Detection & Response

Sigma Rules

The following rules target web server logs (Apache/nginx) for exploitation attempts against the vulnerable endpoints, and post-exploitation behavior consistent with WordPress admin takeover. Deploy them against your web access log pipeline.

YAML
---
title: WordPress DevKit Pro revert_switch Exploitation Attempt - CVE-2026-14378
id: 3b8f2a91-6c4d-4e7a-b912-8f3a5c6d7e8f
status: experimental
description: Detects HTTP requests to the DevKit Pro revert_switch handler carrying an original_user_id cookie, indicative of CVE-2026-14378 authentication bypass attempts targeting administrator account takeover.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-14378
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.initial_access
  - attack.t1190
logsource:
  category: webserver
  product: linux
detection:
  selection_uri:
    c-uri|contains:
      - 'revert_switch'
      - 'devkit'
  selection_cookie:
    cs-cookie|contains: 'original_user_id'
  condition: selection_uri and selection_cookie
falsepositives:
  - Legitimate use of DevKit Pro user-switching by site administrators (validate against source IP and authenticated admin sessions)
level: high
---
title: WordPress JSON API Auth Suspicious Token Reuse - CVE-2026-97637
id: 9d4e7b12-3a5f-4c8d-9e1f-2b6a7c8d9e0f
status: experimental
description: Detects repeated successful authentication responses from the JSON API Auth plugin endpoint from a single source in a short window, consistent with cached session cookie replay or token validation bypass attempts.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-97637
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.initial_access
  - attack.t1190
  - attack.t1078
logsource:
  category: webserver
  product: linux
detection:
  selection:
    c-uri|contains:
      - '/api/auth/'
      - 'json-api-auth'
      - 'generate_auth_cookie'
      - 'validate_auth_cookie'
    sc-status:
      - 200
  condition: selection
falsepositives:
  - Mobile applications legitimately validating auth cookies against the JSON API Auth endpoint
level: medium
---
title: WordPress Admin Account Creation Following Plugin Endpoint Access
id: 5c2d8e34-7b1a-4f6c-a3d9-4e8b9c0d1e2f
status: experimental
description: Detects webshell deployment or administrative account manipulation artifacts on WordPress hosts by identifying PHP process execution of user creation or capability modification functions following unauthenticated plugin endpoint access. Apply on web server file/process telemetry.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-14378
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.persistence
  - attack.t1136
  - attack.t1505.003
logsource:
  category: file_event
  product: linux
detection:
  selection_paths:
    TargetFilename|contains:
      - '/wp-content/uploads/'
      - '/wp-content/plugins/'
      - '/wp-content/themes/'
  selection_ext:
    TargetFilename|endswith:
      - '.php'
      - '.phtml'
      - '.phar'
  condition: all of selection_*
falsepositives:
  - Legitimate plugin/theme updates and media uploads containing PHP templates; correlate with web request source IPs and admin session activity
level: medium

A note on tuning: the third rule will generate volume on busy WordPress hosts because plugin updates legitimately write PHP files under wp-content. The value comes from correlation — alert when a PHP file write under uploads/ (which should almost never contain executable PHP) coincides with unauthenticated requests to the vulnerable plugin endpoints, or when the writing process is the web server user and no corresponding admin session exists.

KQL Hunt — Microsoft Sentinel

This query assumes web server logs are ingested via Syslog/CEF or the W3CIISLog/AzureDiagnostics tables. It hunts for requests to the vulnerable plugin endpoints, cookie-based identity manipulation, and API auth anomalies.

KQL — Microsoft Sentinel / Defender
// Hunt for CVE-2026-14378, CVE-2026-19660, CVE-2026-97637 exploitation attempts
// Adjust table name to your ingestion pipeline (Syslog with Apache/nginx parsed fields, CommonSecurityLog, or W3CIISLog)
let SuspiciousURIs = dynamic(["revert_switch", "devkit", "json-api-auth", "generate_auth_cookie", "validate_auth_cookie", "/api/auth/", "divi-membership", "divi_membership"]);
Syslog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_any (SuspiciousURIs)
| extend HasUserIdCookie = SyslogMessage has "original_user_id"
| extend Uri = extract(@"GET ([^ ]+)", 1, SyslogMessage)
| extend SrcIP = extract(@"(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})", 1, SyslogMessage)
| summarize RequestCount = count(), DistinctURIs = dcount(Uri), CookieAttempts = countif(HasUserIdCookie), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SrcIP, Computer
| where CookieAttempts > 0 or RequestCount > 20
| order by CookieAttempts desc, RequestCount desc

For environments with Microsoft Defender for Endpoint on the web tier, layer in post-exploitation hunting for the web server process spawning unexpected children — a classic webshell indicator:

KQL — Microsoft Sentinel / Defender
// Webshell behavior: web server/PHP processes spawning shells or recon commands
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName in~ ("apache2", "httpd", "nginx", "php-fpm", "php-cgi.exe", "w3wp.exe")
| where FileName in~ ("bash", "sh", "dash", "cmd.exe", "powershell.exe", "whoami", "id", "curl", "wget", "nc", "ncat", "base64")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine, AccountName, InitiatingProcessCommandLine
| order by TimeGenerated desc

Velociraptor VQL

If you suspect compromise on a WordPress host, this VQL artifact hunts for recently written PHP files in upload directories (prime webshell real estate) alongside active web server processes:

VQL — Velociraptor
-- Hunt for recently modified PHP files in WordPress upload/content directories
-- and enumerate web server child processes for webshell indicators
SELECT FullPath, Mtime, Size,
       pslist(Pid=0) AS Processes
FROM glob(globs=['/var/www/**/wp-content/uploads/**/*.php',
                 '/var/www/**/wp-content/uploads/**/*.phtml',
                 '/srv/www/**/wp-content/uploads/**/*.php',
                 '/home/**/public_html/wp-content/uploads/**/*.php'])
WHERE Mtime > now() - 1209600
ORDER BY Mtime DESC
VQL — Velociraptor
-- Enumerate processes running as the web server user with suspicious children
SELECT Pid, Ppid, Name, CommandLine, Username, CreateTime
FROM pslist()
WHERE Username =~ 'www-data|apache|nginx|nobody'
  AND Name =~ 'bash|sh|dash|python|perl|nc|ncat|socat'

PHP files appearing under uploads/ with recent modification times and no corresponding legitimate media-plugin activity are high-confidence webshell candidates. Pull them for analysis before deleting.

Remediation and Verification Script

The following Bash script inventories a Linux-hosted WordPress installation for the three vulnerable plugins, reports their versions, and flags suspicious artifacts. Run it on each web host (adapt WP_ROOT to your docroot):

Bash / Shell
#!/bin/bash
# Security Arsenal - WordPress plugin CVE triage script
# CVE-2026-14378 (DevKit Pro), CVE-2026-19660 (Divi Membership), CVE-2026-97637 (JSON API Auth)

WP_ROOT="/var/www/html"   # adjust to your document root
PLUGINS_DIR="$WP_ROOT/wp-content/plugins"

echo "=== Vulnerable Plugin Inventory ==="
for plugin in devkit-pro divi-membership json-api-auth; do
  if [ -d "$PLUGINS_DIR/$plugin" ]; then
    echo "[FOUND] $plugin installed at $PLUGINS_DIR/$plugin"
    grep -ri "Version:" "$PLUGINS_DIR/$plugin" --include="*.php" -m1 | head -1
  else
    echo "[OK] $plugin not present"
  fi
done

echo ""
echo "=== Deactivated-but-present check (still exploitable in many configurations) ==="
wp plugin list --path="$WP_ROOT" --format=table 2>/dev/null | grep -Ei "devkit|divi-membership|json-api-auth" || echo "wp-cli not available or no matches"

echo ""
echo "=== Recent access log hits on vulnerable endpoints (last 3 days of logs) ==="
grep -hE "revert_switch|json-api-auth|generate_auth_cookie|validate_auth_cookie|divi-membership" \
  /var/log/apache2/access.log* /var/log/nginx/access.log* 2>/dev/null | tail -50

echo ""
echo "=== PHP files modified in uploads/ in the last 14 days (webshell indicator) ==="
find "$WP_ROOT/wp-content/uploads" -name "*.php" -mtime -14 -type f 2>/dev/null

echo ""
echo "=== Recently created admin users (check against change records) ==="
wp user list --role=administrator --path="$WP_ROOT" --fields=ID,user_login,user_email,user_registered --format=table 2>/dev/null || echo "wp-cli not available"

Treat any revert_switch hits accompanied by an original_user_id cookie, any unexpected admin accounts, and any PHP in uploads/ as incident-response triggers, not cleanup tasks. If you find them, preserve logs and site files before remediation — you are in IR territory.

Remediation

  1. Identify exposure immediately. Inventory every WordPress instance in your environment — including marketing microsites, staging servers, and client-hosted properties — for DevKit Pro, Divi Membership, and JSON API Auth. Deactivated plugins with code still present on disk can remain exploitable in some configurations; "inactive" is not "safe."

  2. Patch or remove. Update DevKit Pro to a version later than 2.3.0 as soon as the vendor releases the fix. For Divi Membership and JSON API Auth, pull the vendor advisories and apply the fixed versions immediately. If no patch is available at time of reading, remove the plugin entirely — an authentication bypass at CVSS 9.8 with public technical details has no acceptable workaround-based risk posture. Deactivate-and-delete, and verify removal of plugin directories from wp-content/plugins/.

  3. Virtual patching where removal is not immediately possible. If a business dependency prevents immediate removal, apply WAF rules blocking requests to the revert_switch handler containing an original_user_id cookie, and restrict access to the JSON API Auth endpoints (generate_auth_cookie, validate_auth_cookie) to known application source IPs. Understand that WAF rules are a bridge, not a fix.

  4. Assume compromise for internet-exposed instances. For any site that has been publicly reachable with DevKit Pro ≤ 2.3.0 installed since disclosure: review admin user lists for unauthorized accounts, audit wp-content/uploads/ and theme/plugin directories for unexpected PHP files, review authentication logs for anomalous admin sessions, and rotate all administrative credentials and WordPress salts/keys (wp-config.php). For JSON API Auth deployments, invalidate all existing session cookies/tokens.

  5. Harden persistently. Enforce MFA on all WordPress admin accounts, disable the built-in theme/plugin file editor (define('DISALLOW_FILE_EDIT', true); in wp-config.php), restrict admin area access by IP where feasible, and block PHP execution in wp-content/uploads/ at the web server layer. These controls won't stop the initial bypass, but they sharply limit what an attacker can do with a hijacked admin session.

  6. Track KEV status. Monitor the CISA Known Exploited Vulnerabilities catalog for all three CVEs. If added, federal civilian agencies will face Binding Operational Directive deadlines, and the rest of us get a reliable signal that exploitation is confirmed and widespread.

The pattern across all three CVEs is the same lesson WordPress defenders have re-learned for over a decade: the plugin ecosystem is the attack surface. Authentication logic in plugins receives a fraction of the scrutiny WordPress core gets, and cookie/session trust boundaries are exactly where that scrutiny gap shows up. Patch fast, hunt back, and treat plugin inventory as a first-class vulnerability management discipline — because this will not be the last trio of 9.8s out of the WordPress ecosystem in 2026.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.